HomeBlog › SOC 2 Trust Services Criteria Explained: The Five Criteria and How to Scope Them

SOC 2 Trust Services Criteria Explained: The Five Criteria and How to Scope Them

Published 2026-08-18 · 6 min read · BALTUM

Every SOC 2 report evaluates a company's controls against the Trust Services Criteria (TSC) developed by the AICPA. They define exactly what the auditor will test and what the report will attest to. This article explains all five SOC 2 criteria (Security, Availability, Processing Integrity, Confidentiality and Privacy) and helps you decide which ones to include in scope.

What the Trust Services Criteria are

The TSC are a set of criteria a CPA firm uses to evaluate a service organisation's system of controls. The current edition is TSC 2017, with points of focus revised in 2022. The criteria do not prescribe specific technologies; they describe the outcome the company must achieve, and you choose how to achieve it. The auditor assesses whether your controls are adequate for the criterion and, for Type 2, whether they operated throughout the period.

There are five criteria. Security is mandatory for every SOC 2 report; the other four are included as needed.

CriterionWhat it coversRequired?Who usually needs it
SecurityProtection against unauthorised access and disclosureMandatoryEveryone
AvailabilityThe system is available as committedOptionalSaaS with SLAs, hosting, managed services
Processing IntegrityProcessing is complete, accurate, timely, authorisedOptionalFintech, payments, payroll, analytics
ConfidentialityConfidential information protected through its life cycleOptionalB2B with sensitive client data, outsourcing
PrivacyPersonal data handled per notice and commitmentsOptionalProducts that process individuals' data directly

1. Security: the Common Criteria

The Security criterion underpins the whole report, which is why it is also called the Common Criteria (CC). It consists of nine groups, CC1 to CC9:

  • CC1 Control environment — management accountability, organisational structure, staff competence, code of conduct.
  • CC2 Communication and information — policies communicated to staff, customers informed of commitments, channels for reporting incidents.
  • CC3 Risk assessment — identification and analysis of risks, including fraud risk and the risk of change.
  • CC4 Monitoring activities — internal reviews, vulnerability scanning, evaluation of control effectiveness.
  • CC5 Control activities — selection and deployment of controls, including technology controls, through policies and procedures.
  • CC6 Logical and physical access — the largest group: account management, MFA, least privilege, access revocation, encryption, physical security.
  • CC7 System operations — anomaly detection, incident response, recovery.
  • CC8 Change management — infrastructure and code changes are authorised, tested and documented.
  • CC9 Risk mitigation — business continuity and vendor risk management.

Typical controls: MFA on all corporate systems, quarterly access reviews, same-day offboarding with access revocation, code review before deployment, centralised logging, an incident response plan, annual security training, assessment of critical vendors.

2. Availability

This criterion tests whether the system is available for operation and use as committed to customers. It is not about "100% uptime" but about your ability to deliver the promised service level and to recover when things go wrong.

Typical controls: performance and capacity monitoring, infrastructure redundancy, regular backups with restore testing, a disaster recovery plan tested annually, outage response procedures. Include this criterion if your contracts contain SLAs or if customers depend on your system in real time.

3. Processing Integrity

This criterion concerns whether system processing is complete, accurate, timely and authorised. It matters for systems where a calculation error has direct financial or legal consequences: payment platforms, billing, payroll, reporting, decision-support analytics.

Typical controls: input validation, checksums and reconciliations, error and queue handling, processing logs, data quality controls, correction procedures. For most "ordinary" SaaS products this criterion is unnecessary, and including it "just in case" only increases the audit fee.

4. Confidentiality

This criterion tests whether information designated as confidential is protected from receipt to destruction. Confidential information means data whose use is restricted by contract or law: customers' trade secrets, source code, financial data, deal terms.

Typical controls: data classification, encryption at rest and in transit, NDAs with staff and vendors, need-to-know access restrictions, retention and secure disposal policies. The criterion is relevant for outsourcing companies working with client code and data, and for B2B products handling sensitive information.

5. Privacy

The most extensive optional criterion. It concerns personal information (data about individuals) and evaluates the full life cycle: notice, choice and consent, collection, use, retention, data subject access, disclosure to third parties, data quality, monitoring. Structurally it is close to GDPR requirements, although not identical.

It is important to distinguish: Confidentiality protects any restricted data; Privacy specifically covers individuals' personal data and their rights. Include the Privacy criterion when you determine how personal data is processed (for example, a B2C product) rather than merely processing it on a customer's instructions. In B2B scenarios it is often replaced by the Confidentiality criterion plus separate GDPR compliance.

How to choose criteria for your report

  1. Look at customer contracts and questionnaires. If customers ask about SLAs and recovery, include Availability. If they hand you code and commercial data, include Confidentiality.
  2. Consider the nature of the product. Payments, billing, calculations point to Processing Integrity. Personal data you control points to Privacy.
  3. Do not over-scope. Each criterion means additional controls, evidence and auditor hours. The most common SaaS set is Security + Availability, often with Confidentiality.
  4. Plan for expansion. A first report can cover Security alone, with further criteria added the following year if the market demands it.

Points of focus: how to read the criteria

For each criterion the AICPA provides "points of focus": examples of what to consider when designing controls. They are not mandatory requirements; the auditor does not deduct marks for every unaddressed point, but uses them as a guide. A practical tip: during the gap analysis, walk through the points of focus. It is the fastest way to understand what the auditor expects.

Relationship to other frameworks

Most Security controls overlap with ISO 27001 Annex A, so companies serving both markets often prepare for both at once; see the comparison SOC 2 vs ISO 27001 and the SOC 2 + ISO 27001 package. If you are new to the subject, start with what SOC 2 is, and for the difference between report types read Type 1 vs Type 2.

Not sure which criteria belong in your SOC 2 scope? We will run a gap analysis against the TSC points of focus, recommend the optimal set of criteria and prepare your company for the audit by the BALTUM group's US CPA firm. Request a consultation.